SY0-301 · Question #567
Joe, a technician at the local power plant, notices that several turbines had ramp up in cycles during the week. Further investigation by the system engineering team determined that a timed .exe…
The correct answer is A. Create a VLAN for the SCADA. Segmenting the SCADA network onto its own VLAN isolates critical industrial control systems from other network segments, limiting the ability of malware or unauthorized users to reach the control console. Network isolation is the primary defense-in-depth measure for ICS/SCADA…
Question
Joe, a technician at the local power plant, notices that several turbines had ramp up in cycles during the week. Further investigation by the system engineering team determined that a timed .exe file had been uploaded to the system control console during a visit by international contractors. Which of the following actions should Joe recommend?
Options
- ACreate a VLAN for the SCADA
- BEnable PKI for the MainFrame
- CImplement patch management
- DImplement stronger WPA2 Wireless
How the community answered
(29 responses)- A69% (20)
- B3% (1)
- C17% (5)
- D10% (3)
Why each option
Segmenting the SCADA network onto its own VLAN isolates critical industrial control systems from other network segments, limiting the ability of malware or unauthorized users to reach the control console. Network isolation is the primary defense-in-depth measure for ICS/SCADA environments.
Creating a dedicated VLAN for the SCADA network segments it from the rest of the corporate network, which would prevent the type of access the contractors exploited to upload malicious files to the system control console. VLAN segmentation enforces access control boundaries so that only authorized systems can communicate with industrial control equipment. This is a foundational ICS security control recommended by NIST and ICS-CERT to protect operational technology from IT network threats.
Enabling PKI for the mainframe addresses certificate-based authentication but does not isolate the SCADA network from external access or prevent unauthorized file uploads via physical or network access.
Patch management would address software vulnerabilities but does not prevent the network-level access that allowed contractors to upload the malicious executable to the control console.
Implementing WPA2 wireless security addresses wireless authentication but is irrelevant if the malware was uploaded through a wired connection or physical console access during the contractors' visit.
Concept tested: SCADA network segmentation using VLANs
Source: https://www.cisa.gov/sites/default/files/publications/Securing_Network_Infrastructure_Devices_S508C.pdf
Topics
Community Discussion
No community discussion yet for this question.